Microsoft Warns of New Attack

In a security advisory, Microsoft states it is investigating reports of targeted attacks using a vulnerability in the Microsoft Jet Database Engine that can be exploited through Microsoft Word.

According to the advisory, customers running Windows Server 2003 Service Pack 2, Windows Vista, and Windows Vista Service Pack 1 are not vulnerable to the buffer overrun being attacked, as they include a version of the Microsoft Jet Database Engine that is not vulnerable to this issue.  However, customers using Microsoft Word 2000 Service Pack 3, Microsoft Word 2002 Service Pack 3, Microsoft Word 2003 Service Pack 2, Microsoft Word 2003 Service Pack 3, Microsoft Word 2007, and Microsoft Word 2007 Service Pack 1 on Microsoft Windows 2000, Windows XP, or Windows Server 2003 Service Pack 1 are vulnerable to these attacks.

To read more visit
http://www.pcworld.com/article/id,143749-pg,1/article.html

For the original Microsoft advisory visit
http://www.microsoft.com/technet/security/advisory/950627.mspx

MS Jet Database MS Word